TwinCloud: A Client-Side Encryption Solution for Secure Sharing on Clouds Without Explicit Key Management
نویسندگان
چکیده
With the advent of cloud technologies, there is a growing number of easy-to-use services to store files and share them with other cloud users. Cloud service providers try to convince users to trust their services and encourage them to store personal files or corporate documents on their servers. However, both security conscious personal and cooperate users are reluctant to trust cloud service providers. Although, there are several third-party solutions to provide security in clouds, they are not used extensively because of usability issues. In this paper, we propose a novel solution, TwinCloud. TwinCloud is an innovative cloud storage solution which goal is to provide a secure cloud system to users without compromising any of the advantages the clouds have to offer. TwinCloud achieves this by solving the complex key exchange problem in sharing. It uses a simple and practical approach to store and share files by hiding all the cryptographic and key-distribution operations from cloud users. Serving as a gateway, TwinCloud uses two or more separate cloud providers and symmetric key encryption to store the encryption keys and encrypted files in separate clouds which ease the sharing process without conceding security. A usability study for TwinCloud is also included in the paper. This paper presents TwinCloud and compares it to other cloud storage systems. Keywords-cloud storage; file sharing; key management
منابع مشابه
ZeroDB white paper
ZeroDB is an end-to-end encrypted database that enables clients to operate on (search, sort, query, and share) encrypted data without exposing encryption keys or cleartext data to the database server. The familiar client-server architecture is unchanged, but query logic and encryption keys are pushed client-side. Since the server has no insight into the nature of the data, the risk of data bein...
متن کاملComputationally secure multiple secret sharing: models, schemes, and formal security analysis
A multi-secret sharing scheme (MSS) allows a dealer to share multiple secrets among a set of participants. in such a way a multi-secret sharing scheme (MSS) allows a dealer to share multiple secrets among a set of participants, such that any authorized subset of participants can reconstruct the secrets. Up to now, existing MSSs either require too long shares for participants to be perfect secur...
متن کامل"To Share or not to Share" in Client-Side Encrypted Clouds
With the advent of cloud computing, a number of cloud providers have arisen to provide Storage-as-a-Service (SaaS) offerings to both regular consumers and business organizations. SaaS (different than Software-as-a-Service in this context) refers to an architectural model in which a cloud provider provides digital storage on their own infrastructure. Three models exist amongst SaaS providers for...
متن کاملSecure Hardware-Based Public Cloud Storage
The storage of data on remote systems such as the public cloud opens new challenges in the field of data protection and security of the stored files. One possible solution for meeting these challenges is the encryption of the data at the local device, e.g. desktop, tablet, or smartphone, prior to the data transfer to the remote cloud-based storage. However, this approach bears additional challe...
متن کاملSecure Deduplication of Encrypted Data without Additional Servers
Encrypting data on the client-side before uploading it to cloud storage is essential for protecting users’ privacy. However client-side encryption is at odds with the standard practice of deduplication in cloud storage services. Reconciling client-side encryption with cross-user deduplication has been an active research topic. In this paper, we present the first secure cross-user deduplication ...
متن کاملذخیره در منابع من
با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید
عنوان ژورنال:
- CoRR
دوره abs/1606.04705 شماره
صفحات -
تاریخ انتشار 2016